Core technical questions specific to incident response and crisis management.
Severity levels, impact assessment, business criticality
Initial assessment, containment, escalation procedures
Asset identification, impact analysis, timeline reconstruction
Attack types, threat actors, TTPs, business impact
Stakeholder communication, executive updates, external coordination
Decision matrix, authority levels, notification protocols
Role assignment, coordination, resource allocation
Critical systems, recovery procedures, service restoration
Network isolation, system quarantine, access revocation
Evidence preservation, chain of custody, analysis techniques
Malware removal, system restoration, security hardening
System restoration, service validation, monitoring
Lessons learned, process improvement, documentation
Executive summaries, technical details, recommendations
Process updates, tool improvements, training programs
MTTR, MTTC, incident frequency, resolution quality
Real-world scenarios to test your practical incident response skills.
Containment, communication, recovery, lessons learned
Scope assessment, notification, remediation, compliance
Advanced analysis, long-term monitoring, attribution
Behavioral analysis, access control, legal considerations
Team coordination, communication, resource allocation
Executive updates, business impact, decision support
Legal requirements, regulatory compliance, evidence handling
Customer communication, vendor coordination, public relations
Essential tools and technologies every incident responder should know.